Skip to main content

Fraud Classification

TL;DR
  • Who did it? First-party (your customer) vs Third-party (stolen card) vs Fake identity
  • Your response differs: 3DS for third-party, evidence collection for friendly fraud, device blocking for rings
  • Chargeback impact: Third-party = hard to win (use 3DS), Friendly fraud = winnable with evidence
  • Quick classification helps you pick the right defense

A quick reference for identifying what type of fraud you're dealing with.


Quick Classification

What You SeeLikely TypeYour Response
Customer disputes legitimate purchaseFriendly FraudCollect evidence, fight with CE 3.0
Stolen card used at checkoutThird-Party FraudEnable 3DS for liability shift
Same device, many accountsFraud RingDevice fingerprinting, block infrastructure
Burst of small transactionsCard TestingVelocity rules, CAPTCHA
Good customer acting strangeAccount TakeoverMFA, behavioral analytics
Excessive returns/refundsRefund FraudPolicy enforcement, tracking
Promo/coupon abusePromo AbuseDevice linking, limits
Fake account signupsAccount FraudEmail/phone verification
Mismatched identity infoFake IdentityIdentity verification

By Actor

First-Party Fraud (Your Customer)

The customer is real and uses their own identity, but abuses your policies.

SubtypeDescriptionDefense
Friendly FraudDisputes legitimate purchaseEvidence collection, CE 3.0
Refund FraudExploits return policiesPolicy enforcement
Promo AbuseGames promotions/discountsDevice linking, limits

Chargeback outcome: Winnable with proper evidence

Third-Party Fraud (External Fraudster)

Someone uses stolen payment credentials at your store.

SubtypeDescriptionDefense
Stolen CardUses compromised card3D Secure, AVS/CVV
Card TestingValidates stolen cardsVelocity rules, CAPTCHA
Account TakeoverHijacks customer accountMFA, behavioral analytics

Chargeback outcome: Hard to win unless you have 3DS liability shift

Fake Identity Fraud

Fraudster creates fabricated or mixed identity information.

SubtypeDescriptionDefense
Fake IdentityFabricated personaIdentity verification
Account FraudFake account signupsEmail/phone verification

Chargeback outcome: Sometimes winnable with identity mismatch evidence

Organized Fraud

Coordinated attacks across multiple accounts.

SubtypeDescriptionDefense
Fraud RingsMulti-account attacksDevice fingerprinting, consortium data
TriangulationThree-party resale schemeShipping address analysis

Chargeback outcome: Document network evidence for representment


Classification Decision Tree


Response by Classification

Fraud TypeImmediate ActionPreventionChargeback Strategy
Friendly FraudCollect delivery proofClear descriptors, communicationCE 3.0, device data
Third-PartyCancel/refund if caughtEnable 3DSRely on liability shift
Card TestingBlock IP/deviceVelocity limits, CAPTCHAN/A (usually declined)
ATOLock account, notify customerMFA, device recognitionShow account compromise
Refund FraudFlag accountEnforce policiesDocument abuse pattern
Promo AbuseRevoke benefitsDevice linkingN/A (usually internal)
Fraud RingBlock infrastructureDevice fingerprintingShow organized pattern